Rendered at 11:17:32 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
yellow_lead 16 hours ago [-]
At one point in the article, the author asks Cloudflare's bot if they're launching a Wallet product, and it says no.
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
devindotcom 15 hours ago [-]
heh yeah I ran into this with one of the few times I used claude desktop. it had no idea what features it had and didn't have, where buttons were in the app, etc. isn't that kind of a core category of knowledge you'd want the chatbot to know?
fl0id 14 hours ago [-]
in my experience, usually it knows this (it is in the system prompt) but it can still get confused. Especially with skills for example, some skills might only work in claude code/outside of sandbox or in desktop but not on web. And it would sometimes not know if it was on the web or desktop.
hahahaa 14 hours ago [-]
The next AI benchmark is can an agent understand the product suite of its creators.
strictnein 11 hours ago [-]
That would be an amusing test with AWS.
nitwit005 13 hours ago [-]
That would clearly be superhuman intelligence, as I suspect the employees would struggle with that one.
mattmanser 13 hours ago [-]
Things like this change fast, it has a skill it can use now to find out. I'm not sure when they added it, I only noticed it last week.
inigyou 14 hours ago [-]
The point is to show how AI you are.
MichaelZuo 13 hours ago [-]
Why would Cloudflare want to lose credibility and reputation though? Doesnt seem to make sense.
inigyou 13 hours ago [-]
Credibility and reputation with who? Their target audience is rich people, who love AI.
bakugo 16 hours ago [-]
The point is to signal to investors that they're all-in on the current fad, thus making the stock price go up.
frollogaston 9 hours ago [-]
Half the time, those bots don't even respond
mirashii 16 hours ago [-]
What’s the point? To save money paying a human to man a support email. That human would have also been hopelessly uninformed for all the same reasons.
sholladay 16 hours ago [-]
> That human would have also been hopelessly uninformed for all the same reasons.
Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.
In fact, they would have likely already heard about the new product at lunch or something.
munk-a 16 hours ago [-]
Most chat support people were contractors hired from third party companies that were given dossiers about their products that were often quite out of date because poor management has always been a thing.
sgarman 15 hours ago [-]
Last time Coinbase had a breach I wrote in to support chat to see what I needed to do. They said there was no breach. I sent them a link to their own blogpost about it. They responded with "wow this is the fist time I'm hearing about this."
vntok 15 hours ago [-]
> At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.
Of course not. The extremely vast majority of support staff aren't connected to "internal people" and certainly don't have any access to the main company's Slack.
Most of all, those people are paid very little on very tight length-per-interaction targets. They can't spend any time at all looking for stuff outside the docs package or chatting with peeps outside the immediate costaff.
sandeepkd 15 hours ago [-]
Its an organic cycle, as the company grows big the number of relevant areas grow too and inter team communication becomes way too costly/impractical. The big company becomes a group of informal small companies, each running in their own direction and at times competing with each other. Areas like customer support are not really good candidate for career growth so they get least resources and manpower.
sholladay 15 hours ago [-]
Everything I said applies to overseas labor, too. I’ve worked at both types of companies, those that co-locate support with the product teams, and those that pay bottom dollar and don’t care at all about support.
With the latter type, there’s still almost always a line of communication to corporate. And the support staff still try to help. They are decent human beings, even if the end result kind of sucks.
Groxx 16 hours ago [-]
If you have no training or knowledge-base to search, sure. But then you'd be an awful support-team employer.
saghm 15 hours ago [-]
I mean, yes? That sounds pretty accurate for most companies before chatbots became the new hot thing
Groxx 11 hours ago [-]
The vast majority of people I know who have done phone/chat support have had a spreadsheet (or fancier tool) of common phrases and mandatory boilerplate answers, an overview of the company they're doing it for (sometimes just a couple pages in a word doc), and tone/tool training at a minimum. And generally that tool has a tree of common steps that are also generally mandatory, because they punish rather harshly for going off-script. It's not much, and it gets you the sort of support that people often think of with ticketing systems: impersonal and inaccurate, favoring the company.
But it's rarely this inaccurate. Or if it is (e.g. missing a major product launch), it's fixed in a day or two.
SoftTalker 15 hours ago [-]
Uninformed chatbot replaces uninformed person. And the chatbot doesn't need bathroom breaks or health insurance.
wslh 16 hours ago [-]
And as a dark pattern it adds "positive friction" for the company reducing the number of people that will have the motivation of obtaining the real people support.
saghm 15 hours ago [-]
Several weeks ago I had an issue not being able to login to Verizon's website, so I tried to chat with someone. The chatbot that was gatekeeping was predictably useless said it would redirect me to a human except...it kept prompting me to log in first. It was literally impossible to differentiate from if they literally had no humans online to talk to at all.
mihaaly 16 hours ago [-]
I could be the best money saver for them - and ask for a hefty premium for my services - by terminating all support. No costs, nada, full save! Genius, right?! Never gives false info, never!
Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experience anyway, right?
claudetard 14 hours ago [-]
To avoid wasting customer time, simply make that button close the window.
mihaaly 3 hours ago [-]
That's even better! They can start a complaint about the button by contacting the support, of course.
16 hours ago [-]
ozim 15 hours ago [-]
Web Developers, please follow every best practice, I’m begging you
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
hahahaa 14 hours ago [-]
Who do we call? CTOs I guess.
Yizahi 10 minutes ago [-]
Ghostbusters!
inigyou 14 hours ago [-]
Who made the website?
technion 13 hours ago [-]
Dies it matter? Im sitting on the ops end of this myself right now where marketing purchased something like 15 new domains on Godaddy and both me and the Web developers that built the new site found it the new product will live on those domains and launches today.
This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
12345ieee 8 hours ago [-]
I had marketing close their godaddy account and centralized the domain request flow to the ops team, for security reason.
One of the best workflow changes ever implemented, didn't even need to become CTO.
ozim 13 hours ago [-]
Who designed the customer flow?
In TFA there is no single issue of actual things that web developers could be blamed for.
CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.
All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.
63stack 17 hours ago [-]
My main takeaway from this is not that "security is hard" but that cloudflare is pretty incompetent.
madeofpalk 16 hours ago [-]
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
inigyou 14 hours ago [-]
Once upon a time, RuneScape ran a promotion where World of Warcraft players could join a special world with double XP (experience points) or something by clicking this promotion link.
RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...
InsideOutSanta 15 hours ago [-]
Fricken Proton has a separate domain that lists all of their apps, https://protonapps.com/. This absolutely screams "scam", but no, it's real.
Ffs, just put this on apps.proton.me or something so I actually know it's real!
epochbtc 16 hours ago [-]
Ironically, this might be at least partially because the internal security controls at Cloudflare for using or provisioning new domains/subdomains is so difficult and arduous that the team decided the fastest way to go to market is to get an entirely new domain. Possible bonus that the official bug bounty program won't apply either, since it's on a new domain so any vulnerabilities found won't have to be paid out (as much).
OkayPhysicist 16 hours ago [-]
Why is this so, so common? They're subdomains. They're free. It's not hitting anybody's budget to publish a new DNS entry. If someone has permission to publish anything in your name, they probably should be able to go make themselves a subdomain.
edent 15 hours ago [-]
Because they point foo.example.com to AWS. They then let whatever the CNAME is pointing to lapse. Then an attacker registers the lapsed AWS and can now put their content on your trusted domain.
(AWS have since fixed this problem, but it exists on other services.)
saghm 15 hours ago [-]
So the solution is to make it even easier to let the domain records lapse by putting it outside the place where everyone would know about it, with the added bonus that now you can super easily let the domain registration itself lapse without noticing so that your customers who have been told to use it can get directly pwned by whoever grabs it?
14 hours ago [-]
chrisandchris 15 hours ago [-]
Which you could mitigate by using a Cert-Policy in DNS and HTST, so an attacker might not get s valid certificate for your domain and at least access is sonewhat restricted.
peanut-walrus 14 hours ago [-]
Because web security has a lot of legacy crap. Such as cookies. Oh you added Domain=foo.com to your cookie? Now marketingvibecodedapp.foo.com can access the cookie from your main domain. What do you mean you thought adding the domain field restricts the cookie to just that domain? Lol no, it's the exact opposite, gotcha, dumbass.
inigyou 14 hours ago [-]
Because corporate security has nothing to do with security, and everything to do with adding bureaucracy roadblocks to legitimate activity.
epochbtc 15 hours ago [-]
Counter-argument is: do you really want some team of 90% marketers and PMs throwing up a MVP/WIP codebase for some ancillary product not related to your core business on your core domain? At a minimum you'd want a thorough security review and risk assessment, and that goes against the ethos of "ship fast and pivot as needed".
ryandrake 15 hours ago [-]
Why does the TLD matter in this case? How does your security/risk posture change if you launch on myexperiment.mycompany.com vs. www.mycompanyexperiment.website that you had to go out and newly purchase? Asking because I legit don't know.
nvme0n1p1 15 hours ago [-]
One example: a subdomain like experiment.example.com can access cookies for example.com.
saghm 15 hours ago [-]
I mean, it sounds like they're already doing that, just with extra downside
AndrewKemendo 15 hours ago [-]
I’d argue this is exactly why this happened and why the poster is correct but missing the point:
Your organizational management is the problem not the technology
If you can’t coordinate internally to roll out a proper domain then I question how well your teams are managed
1970-01-01 16 hours ago [-]
This isn't a secfail. Why is pay.cloudflare.com so hard to establish? Why does marketing always get to overpower engineering? I expect Cloudflare services to avoid some sketchy .pay TLD for exactly the reasons this person went through.
nemothekid 14 hours ago [-]
>Why is pay.cloudflare.com so hard to establish?
An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc.
> `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is blocked. I don't care that it's a Zig application.
I remember just doing SOC2 for a startup and it made just spinning up an EC2 instance require several steps of rigamarole just to be "in-compliance". And if anything goes wrong? Well why didn't you follow the 2,000 step process?
I don't envy anyone who has to deal with issues like these.
frollogaston 9 hours ago [-]
Probably half those problems are SOP/CORS, which gets in the way in exchange for a false sense of security. I'm on board with ditching that. Websockets already did. (Cookies should still adhere to SOP though.)
marcta 15 hours ago [-]
Presumably the big scary sysadmins have access to the *.cloudflare.com DNS records, and marketing just needs to push this thing right now and can't wait, so it's easier for them to buy a new domain with a shiny new TLD than wait for pay.cloudflare.com to be authorised.
cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such a big company.
hahahaa 14 hours ago [-]
Google manages it though. And you could have a labs.cloudflare.com/idea and make it easy to add new ideas internally.
andremendes 16 hours ago [-]
What a ride of a read. I was 100% it was phishing and I got really surprised to find out it wasn't.
hahahaa 14 hours ago [-]
I thought it wouldn't be as I assume :) CloudFlare scans for new tld and either gets in the sunrise period or at a minimum objects to anyone else registering a straight CloudFlare.tld. But CloudFlarepay.com or cl0udflar3.com have more scam risk.
EGreg 15 hours ago [-]
I only realized it wasnt after googling for the phrase “cloudflare.pay” and finding the announcement on Cloudflare’s own blog, which I trust because it is on cloudflare.com
All the bots including Google’s say it’s a phishing scam site probably, since they don’t know Cloudflare has a wallet product.
Insimwytim 14 hours ago [-]
The Cloudflare folks apparently want security issues reported via HackerOne (which wouldn’t let me log in because the Cloudflare CAPTCHA HackerOne uses seems to be broken…).
That's just gold
stymaar 14 hours ago [-]
So it's not just FedEx[1] who does that, but also one of the most important tech company…
It looks like they've updated the cloudflare.pay site to link to the blog post on cloudflare.com that introduces wallets. So they fixed it on the same day they launched. That's not too bad, in my book.
saghm 15 hours ago [-]
I mean, what would stop someone from registering mycloudflare.pay and doing the same thing? Having the link in the other direction seems like what matters more
Joker_vD 14 hours ago [-]
By "the same thing", you mean writing the blog post on Cloudflare's official blog?
inigyou 14 hours ago [-]
No, they mean making it link to the blog.
joemi 13 hours ago [-]
I mentioned it because the blog post itself links back to cloudflare.pay. Of course just linking to a blog post is useless.
dwedge 16 hours ago [-]
I guess it's easy to judge from the sidelines but was the screenshot of the site, if not the first tweet, not an obvious scam? And you can say it's from context but I only read the title before my eyes jumped to the screenshot
dwedge 16 hours ago [-]
I just read the rest of the article and I'm back with my tail between my legs. I guess I made the author's point.
Hovertruck 16 hours ago [-]
Don't worry, I think everyone probably went on the same roller coaster with this one
thadt 16 hours ago [-]
In the movie Sneakers, a whole scene is taken up sending some guy on a date with Mary McDonnell so she could record clips of his voice. Today she'd just need a phone call or his Instagram. It's getting harder to keep up with who _people_ are online, much less organizations and domain names.
Identity is hard y'all.
saghm 15 hours ago [-]
I don't understand what your point is. Do you disagree with any of the concrete suggestions in the blog post about what should have been done differently, or do you think they're hard to follow?
thadt 12 hours ago [-]
The blog’s suggestions are fine. I’m pointing out that this issue is less about “security” and more a problem of “identity”.
And that such issues with identity are likely to increasingly be a problem.
pjmlp 5 hours ago [-]
Security in general is hard.
It starts on developers own machines, which programming languages get used, how dependencies are added to the projects, how testing is done, how code gets written, how inputs and current user roles get validated.
All of this before even exposing the application to a BSD socket.
tchalla 14 hours ago [-]
I tried to signup and got an "Internal Server Error" post the auth callback. Embarrassing for Cloudflare. Par for the vibe coded culture I guess.
tailscaler2026 13 hours ago [-]
[dead]
Joker_vD 17 hours ago [-]
Another entry in "Marketing department starts a promotion campaign for the new product that's indistinguishable from a phishing attack" list. Starting with not using a subdomain on your own, very well-known domain but instead using a completely different one, then not having it shown with the rest of your services on your main web site, et cetera.
raesene9 16 hours ago [-]
Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
It's probably easier for the marketing department to get a new domain up and running that it is for a new subdomain within their own company. Battling Business Units and all that.
saghm 15 hours ago [-]
That's a problem that should be solved then, because literally everyone loses when it's done this way
derektank 16 hours ago [-]
You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains
nerdsniper 16 hours ago [-]
Running marketing off a separate domain is often a conscious decision because if they start getting blocked for spam, then critical service/operational emails from your actual domain might also get blocked.
saghm 15 hours ago [-]
Oh good, I'm glad that Cloudflare, proud defender of internet security, is properly focused on the important goal of optimizing for their ability to send promotional emails to my inbox rather than silly things like helping prevent phishing attacks.
make3 16 hours ago [-]
this is the correct take
12 hours ago [-]
aprilnya 15 hours ago [-]
I saw the whole Cloudflare Pay thing and had the exact same thoughts - this has to be some sort of phishing...
eaf7e281 14 hours ago [-]
I also immediately check to see if it's an actual Cloudflare product because cloudflare[.]pay seems too suspicious to me.
Luckily, Google didn't fail me this time. Found a blog about this product with a link to the same domain.
varenc 13 hours ago [-]
Cosmically I feel like the HTTPS certificate on Cloudflare.pay should provide sufficient info to confirm it's the same entity behind Cloudflare.com
lee_ars 13 hours ago [-]
You'd think, but nope, it def doesn't — the site's TLS cert is issued by Google Trust Services, which issues domain-validated certs via ACME, so no, the only thing the site owner had to do to get that certificate is demonstrate ownership of the `cloudflare.pay` domain. GTS is also one of the default CAs that Cloudflare's universal SSL uses, so that's also exactly what would show up for any Cloudflare-proxied site with TLS enabled.
The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.
The domain's whois is also devoid of identifying details:
Registered through 101domain, with nothing except a registrar abuse contact.
I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.
edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.
frollogaston 9 hours ago [-]
How would that association be shown to the user? Currently we're trained to check that the domain name is the same.
ernsheong 14 hours ago [-]
Cloudflare seems to be trying to do EVERYTHING.
inigyou 13 hours ago [-]
Every company has to try to do everything, before any other company does, especially related ones.
It's why Valve moved into OSes and hardware. If they didn't, Microsoft were holding a nuclear bomb over their heads. It's why Google has a phone platform, because Apple has been replacing the Google apps one-by-one. It's also why Samsung has a parallel suite of apps to the Google ones. It's why the pizzeria makes fries, because they're threatened by the fry shop across the street starting to serve pizza. It's why Uber tried to make self driving taxis. It would be good if the fry shop made only the best fries and the pizza shop made only the best pizza and Valve made only the best game store and Microsoft made only the best OS, but it's a very unstable equilibrium. Does your ISP still give you an email address?
16 hours ago [-]
wackget 16 hours ago [-]
1. Why is this website blocked when I try browsing it using Brave?
2. Why on earth would you want a financial product from a WAF?content delivery company?
aDyslecticCrow 15 hours ago [-]
You didn't read the whole article; it's not a scam, it's a new official cloud-flare product.
j45 14 hours ago [-]
Depending on how possible it is for a use case, reducing the attack surfaces and vectors can help, such as being mindful of how much client side javascript exposes anything.
TZubiri 16 hours ago [-]
this from a company whose main product is (was) security.
I feel there's a generalized decrease in quality in software in general.
LocalH 16 hours ago [-]
Web security wasn't hard before we started trying to make the web a platform for full executable software.
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
OkayPhysicist 16 hours ago [-]
None of this required Javascript. At all. The same potential attack could have been done with good ol' forms. Sure, you think you're signing into "BigBensSuperStore.com", but you're actually handing your credentials right over to "BigBensSuperStore.net".
LocalH 16 hours ago [-]
JavaScript (and other forms of executing logic within the browser) have made the situation worse, though.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
saghm 15 hours ago [-]
If a malicious site gets your password, I'm not sure why it matters whether it happened in the frontend or not.
LocalH 13 hours ago [-]
Bad actors have been social engineering passwords for years even before a single line of JS was written. Restricting the backend is a way of heavily reducing the attack surface. The expansion of hardware access to browsers is the largest scam enabler of the 21st century. The only reason it's happening in the long term is because companies like Google (DoubleClick) wish to use hardware attestation to tie people to hardware for advertisement purposes, and that requires complete vertical attestation.
We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.
I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
applfanboysbgon 15 hours ago [-]
> "The web" was never designed to be an application platform. It was only designed to be a document platform.
And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.
inigyou 13 hours ago [-]
You realize the same argument applies to Word macros.
LocalH 13 hours ago [-]
I think someone should ask Vint Cerf whether he ever intended the web to run executable code, and enforce that answer on the existing web.
I bet the world would crumble. Good.
applfanboysbgon 13 hours ago [-]
This is base stupidity. Suppose you used your web-dictator powers to strip JS from the web based on historical decisions made 50 years ago. Then everyone other than you would use Web2 and ignore you. Indeed Web 2.0 is already a term recognising that the web has changed since it was first conceived; I guess it would make you feel better if we formalised it and formally created a new Web that's exactly like the current Web except with nobody who can claim things about how it was "supposed" to work in the 1970s?
LocalH 13 hours ago [-]
Clearly you have a vested interest in the status quo of today, instead of understanding why the whole network was created in the first place.
Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.
Email has similarly been destroyed by HTML email, at least partially.
It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.
applfanboysbgon 12 hours ago [-]
"The whole network was created in the first place" to serve the needs of a tiny number of academic and military researchers. This legacy is completely irrelevant to why it exists today. Again, we can kill Web1 if it makes you happy, so we can get rid of your tired appeal to "but the 1970s design!!!". If we kill it, then people will just create some new network that serves the actual use cases of billions of people, because there will still be demand for software that does more useful things than sharing documents. And when that new network is created, it will be exactly the same as the current one, but it will have been made in the 2020s, so you can finally STFU about the 1970s. Would engaging in that farce make you happier?
> Your viewpoint enables billions of dollars of fraud every year, worldwide.
Yep. Having knives in every kitchen enables people to be stabbed, too. As a society we choose to allow useful things to exist rather than locking everyone in a straitjacket, even though the latter would be more safe and prevent all kinds of crime and tragedy. It's funny that you complain about centralizing control at the same time as making this argument that nobody should have tools because tools can be misused.
saadyousfi 14 hours ago [-]
[flagged]
iryndin 16 hours ago [-]
[dead]
thataccount 16 hours ago [-]
Cloudflare is your favorite company and they are geniuses?
Dear Diary,
Today my fanboy bubble was burst.
Signed,
Author
ericlaw 16 hours ago [-]
Note that I said: "One of my", and Cloudflare has hired a HUGE percentage of the best networking talent I've encountered.
thataccount 16 hours ago [-]
Another company named Cisco used to do that. They built the Great Firewall of China. Hiring talent does not equal good company.
Panino 16 hours ago [-]
I hadn't read that so I looked it up to verify, and it appears true:
Cisco looks to have made money from repression and torture.
Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.
robocat 13 hours ago [-]
> sites are on Cloudflare
And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house.
Are Cloudflare supposed to be the police?
Does the UN provide a registry list of criminal domains that should not be livened?
inigyou 13 hours ago [-]
Doesn't even matter who CF is hosting - the fact they're sending all our HTTP requests to the NSA should be enough reason already!
sghiassy 16 hours ago [-]
Just use LLMs. They can apparently doing everything and all the things
> There is no such product in our documentation or dashboard, so treat any email, website, or message claiming to be "Cloudflare Wallet" as a phishing attempt.
What's the point of adding these AI chatbots if they're hopelessly uninformed about your products?
Not really. At minimum, a half-way decent support person would ask a few people internally or search Slack before answering.
In fact, they would have likely already heard about the new product at lunch or something.
Of course not. The extremely vast majority of support staff aren't connected to "internal people" and certainly don't have any access to the main company's Slack.
Most of all, those people are paid very little on very tight length-per-interaction targets. They can't spend any time at all looking for stuff outside the docs package or chatting with peeps outside the immediate costaff.
With the latter type, there’s still almost always a line of communication to corporate. And the support staff still try to help. They are decent human beings, even if the end result kind of sucks.
But it's rarely this inaccurate. Or if it is (e.g. missing a major product launch), it's fixed in a day or two.
Ok, ok, need to have a tickmark next to the 'support' item in the quarterlies, let it be an eternal spinning wheel presenting on clicking the 'Our award winning instant support is HERE!' button then. Its close to the real experience anyway, right?
Marketing people just make bunch of marketing domains. Business people push all kind of BS ideas.
No one is asking Web Developers about their opinion man.
STOP making everything developers fault.
This is an entirely normal experience across every org ive worked in and unless im also surprise promoted to cto today I do not have an ability to question it.
One of the best workflow changes ever implemented, didn't even need to become CTO.
In TFA there is no single issue of actual things that web developers could be blamed for.
CSP not mentioned I assume it was correctly configured, site has https, site is using SSO from providers not storing passwords.
All security failures in this instance are stemming from bad customer flow, using silly domain, even "poorly placed" security element was most likely designed to be in that place by some designer not any web developer. While all the other things done by a business/marketing/UX and I bet Cloudflare has loads of cybersecurity people who should be asked to review the customer flow and not a web developer.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...
Ffs, just put this on apps.proton.me or something so I actually know it's real!
https://aws.amazon.com/blogs/security/threat-tactic-spotligh...
(AWS have since fixed this problem, but it exists on other services.)
Your organizational management is the problem not the technology
If you can’t coordinate internally to roll out a proper domain then I question how well your teams are managed
An engineer who vibes up a marketing site, and attempts to put it on the same origin as *.cloudflare.com now has to jump through 1,000 hoops of security clearance, customer notifications, etc.
> `pay.cloudflare.com` can't be launched because it doesn't have the proper WAF preventing 25 year old Wordpress exploits, please make sure pay.cloudflare.com/wp-admin.php is blocked. I don't care that it's a Zig application.
I remember just doing SOC2 for a startup and it made just spinning up an EC2 instance require several steps of rigamarole just to be "in-compliance". And if anything goes wrong? Well why didn't you follow the 2,000 step process?
I don't envy anyone who has to deal with issues like these.
cloudflare.com/pay probably has a similar chain of approval: if every marketing idea had its own top-level route, it would get pretty crazy with such a big company.
All the bots including Google’s say it’s a phishing scam site probably, since they don’t know Cloudflare has a wallet product.
[1]: https://www.troyhunt.com/thanks-fedex-this-is-why-we-keep-ge...
Identity is hard y'all.
And that such issues with identity are likely to increasingly be a problem.
It starts on developers own machines, which programming languages get used, how dependencies are added to the projects, how testing is done, how code gets written, how inputs and current user roles get validated.
All of this before even exposing the application to a BSD socket.
Luckily, Google didn't fail me this time. Found a blog about this product with a link to the same domain.
The cert itself only has CN=cloudflare.pay. It lacks an org, an address, or any other identifying info. It's not OV/EV, so no details there, either.
The domain's whois is also devoid of identifying details:
https://rdap.nominet.uk/pay/domain/cloudflare.pay
Registered through 101domain, with nothing except a registrar abuse contact.
I mean, great that this is legit, but CF could have done a better job with making it actually _look_ legit. This looks sketchy as fuck.
edit - gawd, nevermind. they don't even have anything useful for cloudflare.com. Same GTS cert, redacted whois info. lol. how did we even get here.
It's why Valve moved into OSes and hardware. If they didn't, Microsoft were holding a nuclear bomb over their heads. It's why Google has a phone platform, because Apple has been replacing the Google apps one-by-one. It's also why Samsung has a parallel suite of apps to the Google ones. It's why the pizzeria makes fries, because they're threatened by the fry shop across the street starting to serve pizza. It's why Uber tried to make self driving taxis. It would be good if the fry shop made only the best fries and the pizza shop made only the best pizza and Valve made only the best game store and Microsoft made only the best OS, but it's a very unstable equilibrium. Does your ISP still give you an email address?
2. Why on earth would you want a financial product from a WAF?content delivery company?
I feel there's a generalized decrease in quality in software in general.
I never got hacked through the web before JavaScript (never got hacked after either, yet, but it wasn't really possible in the same way to hack someone through the web without some way to execute program logic, which in the old days would have required a much more specific browser exploit to gain RCE).
JavaScript was a mistake. Everything else after that involves "running code in the browser" was a mistake.
Program execution needs to be completely separate from "the web". I don't want any code of any sort running in my browser, at least not any that I don't fully control. "The web" was never designed to be an application platform. It was only designed to be a document platform.
To me, there's a big difference between a domain misread and actively malicious code running in the browser context as a design point.
We're losing general-purpose computing like frogs in a slow cooker, and millions of people don't even notice. Fuck TPM, fuck hardware attestation, no internet company should get a single bit from me that I don't authorize. Any site that requires hardware attestation will be a hard "no" for me to ever visit again.
I maintain this all started when commerce was introduced to the internet. Things were better before money was transferred digitally. Allowing that was a major fuckup.
And then it expanded to serve the needs of billions of people instead of the needs of a few researchers. Womp, womp. Get over it, use a JS-free browser to browse your documents, and accept that the world has moved on. Or don't, and rant at clouds, I guess.
I bet the world would crumble. Good.
Your viewpoint enables billions of dollars of fraud every year, worldwide. Mine doesn't.
Email has similarly been destroyed by HTML email, at least partially.
It's like there is a coordinated effort to destroy every single legacy protocol and replace it with something centrally controlled. No fucking thank you.
> Your viewpoint enables billions of dollars of fraud every year, worldwide.
Yep. Having knives in every kitchen enables people to be stabbed, too. As a society we choose to allow useful things to exist rather than locking everyone in a straitjacket, even though the latter would be more safe and prevent all kinds of crime and tragedy. It's funny that you complain about centralizing control at the same time as making this argument that nobody should have tools because tools can be misused.
Dear Diary,
Today my fanboy bubble was burst.
Signed,
Author
https://www.eff.org/deeplinks/2016/04/ciscos-latest-attempt-...
Cisco looks to have made money from repression and torture.
Meanwhile a large fraction of neo-nazis, credit card thieves, and DDoS-for-hire sites are on Cloudflare. It takes serious talent (not morals) to attack humanity at scale.
And robbers can hire cars, buy battery angle grinders, and charge the batteries from the electricity network then drive on roads to your house.
Are Cloudflare supposed to be the police?
Does the UN provide a registry list of criminal domains that should not be livened?